TL;DR
- An attacker drained roughly 594 BTC value about $38 million from round 500 Coldcard wallets throughout a coordinated 25-minute sweep early Friday.
- The flaw bypassed {hardware} randomness and generated seeds from predictable chip knowledge, shrinking the key house meant to make non-public keys successfully unguessable.
- Coinkite issued emergency firmware updates, however current weak seeds stay susceptible and should be changed; the corporate suspects AI helped uncover the bug at scale.
A vulnerability in Coldcard {hardware} wallets allowed an attacker to drain roughly 594 BTC, value about $38 million, from round 500 single-signature wallets in solely 25 minutes. The sweep occurred between 01:31 and 01:56 UTC on Friday, shifting funds by way of 500 transactions inside a three-block window with outstanding pace and precision. A tool designed to maintain keys offline as an alternative produced seeds that could possibly be narrowed down and guessed. Investigators traced 562 BTC into one handle that had not moved, whereas proof confirmed many affected wallets had remained dormant for years earlier than the coordinated theft started.
COLDCARD Mk3 Safety Advisory
If you happen to generated a seed on a Mk3 after firmware 4.0.1, your funds could also be in danger.
Mk4, Q and Mk5 aren’t affected primarily based on our early evaluation.
Learn the advisory and migrate fastidiously:https://t.co/3vgPHOjMS7
— COLDCARD (@COLDCARDwallet) July 30, 2026
Predictable system knowledge undermined Coldcard’s randomness
The failure originated in Coldcard firmware launched throughout March 2021. A construct setting brought on gadgets to bypass their {hardware} randomness generator, whereas a supporting-library examine examined solely whether or not that setting existed, not whether or not it was enabled. Key creation then fell again to software program seeded with a chip serial quantity and clock registers, neither of which is secret or genuinely unpredictable to attackers. The supposedly huge search house defending every pockets was decreased by predictable system data. Publicity is determined by the firmware operating when the pockets was created, moderately than when the {hardware} itself was bought.

Coinkite warned customers who generated seeds on Mk3 gadgets operating firmware 4.0.1 or later, whereas describing its conclusions about newer fashions as preliminary. The corporate launched emergency updates for Mk4, Mk5 and Q gadgets, however putting in patched firmware can not strengthen a seed already produced below susceptible situations. Homeowners should create a contemporary seed and switch funds, as a result of software program updates can not rewrite compromised randomness. Really useful safeguards embrace a powerful BIP-39 passphrase, no less than 99 cube rolls, or each, whereas unsupported Mk3 customers face a separate and probably difficult migration course of for safeguarding any remaining balances safely.
The producer believes an attacker might have used synthetic intelligence to examine older variations of its open-source firmware and uncover the flaw. That conclusion stays an assumption, not confirmed attribution, and carries an uncomfortable irony: Coinkite stated its personal AI-assisted evaluate weeks earlier discovered nothing severe. The incident exhibits how the identical analytical instruments can strengthen defenders or speed up exploitation. Past pockets seeds, the flawed generator may have affected paper-wallet keys, seed-splitting masks, cloning keys and Key Teleport transfers, widening the continued safety evaluate past the 594 BTC already stolen from lots of of victims.

